August 31, 2026
Updated: August 31, 2026
How a China-linked APT reached inside the US telecom backbone, and the wiretap system built for American investigators.
Abdalla Mohamed

Salt Typhoon is the China-linked state-sponsored hacking group behind what a US senator called the worst telecommunications hack in American history. Over several years it burrowed into the core networks of AT&T, Verizon, T-Mobile, Lumen, and at least half a dozen other US carriers, and, most alarmingly, into the lawful-intercept systems the US government requires telecoms to build for court-authorized wiretaps. That access let it pull call records, geolocate people, and target the communications of senior US political figures. This guide explains what Salt Typhoon is, how the attack worked, who it hit, how the FBI and CISA responded, where the IOCs live, and how it differs from its infrastructure-focused sibling, Volt Typhoon.
Updated: August 2026. Reflects the joint CISA/FBI/NSA advisory AA25-239A (August 2025), the confirmed telecom victims, and Salt Typhoon's continued activity into 2025-2026.
| Question | Short answer |
|---|---|
| What is it? | A PRC (Chinese) state-sponsored APT, linked to the Ministry of State Security (MSS) |
| What did it do? | Breached US and global telecoms to intercept calls, texts, and metadata |
| Who did it hit? | AT&T, Verizon, T-Mobile, Lumen, and others; at least 200 US organizations and around 600 worldwide |
| The scariest part? | It accessed the CALEA lawful-intercept (wiretap) systems and targeted political figures' comms |
| How did it get in? | Mainly by exploiting unpatched Cisco network devices and living in the routers |
| Is it still active in 2026? | Yes. It remains active and hard to fully evict |
The one line to remember: Salt Typhoon turned the wiretap system the US built for its own investigators into a listening post for Chinese intelligence.
Salt Typhoon is an advanced persistent threat (APT) group attributed to the People's Republic of China, assessed to operate under the Ministry of State Security (MSS) through a network of contractors and front companies. It has been active since at least 2019-2021. "Salt Typhoon" is the name Microsoft assigned it under its weather-themed naming scheme for Chinese state actors; other vendors track overlapping activity as OPERATOR PANDA, RedMike, UNC5807, GhostEmperor, and Earth Estries. In their August 2025 advisory, the US and allied agencies declined to endorse any single commercial name and simply called the actors "APT actors."
Where its sibling Volt Typhoon pre-positions to disrupt infrastructure, Salt Typhoon is a classic, if enormous, espionage operation. Its goal is intelligence: who is talking to whom, from where, and, where possible, the content of those communications.

The campaign was patient and methodical, and it turned on a simple weakness, unpatched network hardware, then escalated into the heart of the telecom.
The victim list reads like a directory of the US communications backbone, and it extends worldwide.
| Victim category | Examples |
|---|---|
| US telecom carriers | AT&T, Verizon, T-Mobile, Lumen, Charter/Spectrum, Consolidated Communications, Windstream, Viasat |
| Global telecoms/ISPs | Providers across Europe and the Indo-Pacific |
| Other sectors (per CISA) | Government, transportation, lodging (hotels), and military networks |
| High-value individuals | Communications of senior US political figures, including Donald Trump, JD Vance, and Kamala Harris campaign staff |
According to the FBI and the August 2025 advisory, the campaign compromised at least 200 US organizations, and by FBI estimates around 600 organizations worldwide across more than 80 countries. The targeting of hotels and transportation is telling: combined with call and location data, it lets Chinese intelligence identify and track the movements and communications of targets around the world. The specific breaches of Verizon and T-Mobile drew particular attention, though both, along with other carriers, later stated they had evicted the actors from their networks.
The scale of Salt Typhoon triggered an extraordinary international response.
For defenders, the single most useful artifact is CISA's advisory itself. AA25-239A ships a downloadable, machine-readable list of indicators of compromise (IOCs) in JSON, alongside detection and threat-hunting guidance. Rather than reproduce volatile indicators here (they change, and stale IOCs create false confidence), the right move is to pull the current list directly from CISA and feed it into your detection stack. The advisory's TTP mapping to MITRE ATT&CK is the more durable resource: hunt for the behaviors, unexpected router configuration changes, GRE tunnels, anomalous administrative access to network devices, and unusual traffic to and from edge infrastructure, not just static indicators.

The two headline Chinese "Typhoon" groups are easy to confuse and do opposite jobs. The contrast is the clearest way to understand each.
| Salt Typhoon | Volt Typhoon | |
|---|---|---|
| Primary goal | Espionage, intercept communications | Pre-position to disrupt critical infrastructure |
| Main targets | Telecom and ISP backbones, government, lodging | Energy, water, transportation, comms (incl. Guam) |
| Signature move | Router exploitation, tapping wiretap systems, rootkits | Living off the land, SOHO-router botnet, OT pivot |
| Value of stolen data | Massive: calls, texts, metadata, wiretap targets | Limited (it's not really spying) |
| Governing CISA advisory | AA25-239A (2025) | AA24-038A (2024) |
In one line: Salt Typhoon listens; Volt Typhoon prepares to break things. We cover the disruptive, infrastructure-focused sibling in our Volt Typhoon analysis, compare them directly in Salt Typhoon vs Volt Typhoon, and both sit within the wider nation-state threat picture in the most notorious hackers.
Salt Typhoon has not stopped. Threat-intelligence reporting through 2025 documented continued exploitation of vulnerable Cisco devices at telecoms and other organizations, and a separate 2024 intrusion into a US National Guard network reportedly went unnoticed for roughly nine months. Carriers have announced they evicted the actors from their networks, but for a group that lives inside routers and trusted connections, "evicted" is a claim that requires continuous verification. As of 2026, Salt Typhoon remains one of the most capable and active espionage threats to global communications infrastructure.
The campaign succeeded on fundamentals, unpatched edge devices and weak network-device hardening, so the defense is fundamentals done rigorously.
| Control | What it addresses |
|---|---|
| Patch internet-facing network devices urgently | Closes the Cisco/Ivanti/Fortinet flaws used for initial access |
| Harden and monitor network-device configs | Detects the router modifications used for persistence |
| Disable unused management services (e.g. Smart Install, web UIs) | Removes the exact features exploited by CVE-2018-0171 and CVE-2023-20198 |
| Centralized logging for network infrastructure | Makes long-dwell router-level activity visible |
| Encrypt communications end to end | Limits the value of intercepted traffic |
| Ingest CISA AA25-239A IOCs and hunt the TTPs | Turns the joint advisory into active detection |
| Network segmentation and least privilege | Slows lateral movement through trusted connections |
Two priorities dominate. First, treat network devices as crown-jewel assets: patch them on the KEV timeline, disable legacy management features, and monitor their configurations, an extension of the discipline in our patch management guide. Second, assume the perimeter can be turned against you: the whole campaign hinged on exposed, exploitable edge devices, which is exactly what external penetration testing is built to find, and a rehearsed incident response plan determines how fast you can respond when it is.
Salt Typhoon is a lesson in where modern espionage actually lands: not on endpoints, but in the network fabric, the routers, edge devices, and trusted connections that most security programs under-monitor. It also punctures the assumption that a nation-state needs zero-days: much of this ran on known, unpatched vulnerabilities in internet-facing gear. For any organization, and especially telecoms, ISPs, and their suppliers, the message is that your network devices are a primary target, your patch cadence on them is a national-security-grade control, and "we removed them" is a hypothesis to keep testing, not a conclusion.
DeepStrike's penetration testing probes the exposed network devices and edge services a group like Salt Typhoon exploits, validates whether an attacker could gain and hold access, and gives you the fixes and detections you need. For US-based teams, see our US penetration testing services.
Salt Typhoon is a Chinese state-sponsored hacking group, linked to the Ministry of State Security, that conducted a large-scale espionage campaign against telecommunications providers. It breached major US carriers including AT&T, Verizon, and T-Mobile to intercept calls, texts, and metadata, and reached the lawful-intercept systems used for court-authorized wiretaps.
Confirmed and reported US telecom victims include AT&T, Verizon, T-Mobile, Lumen, Charter/Spectrum, Consolidated Communications, Windstream, and Viasat, along with telecoms in Europe and the Indo-Pacific. In total, the campaign is assessed to have compromised at least 200 US organizations, and by FBI estimates around 600 organizations worldwide across more than 80 countries, spanning telecom, government, transportation, and lodging.
Advisory AA25-239A, published in August 2025 by CISA, the FBI, the NSA, and more than a dozen allied governments, details the tactics, techniques, and procedures of the Chinese state-sponsored actors behind the Salt Typhoon activity. It provides mitigation guidance and a downloadable list of indicators of compromise (IOCs) for threat hunting.
It primarily exploited vulnerable, internet-facing network devices, especially Cisco gear via flaws like CVE-2023-20198, CVE-2023-20273, and the older CVE-2018-0171 (Smart Install). It then modified routers to persist, used implants such as GhostSpider and the Demodex rootkit, and pivoted through trusted connections into telecom core and lawful-intercept systems.
Because it compromised the communications backbone and the wiretap infrastructure itself. Access to lawful-intercept systems could reveal which people US law enforcement is surveilling, and the actors targeted the communications of senior political figures. It effectively turned a system built for US investigators into a surveillance tool for Chinese intelligence.
Both are Chinese state-sponsored groups, but Salt Typhoon is an espionage operation focused on intercepting communications from telecoms, while Volt Typhoon pre-positions inside energy, water, and transportation infrastructure to enable disruptive attacks in a future conflict. Salt Typhoon listens; Volt Typhoon prepares to break things.
CISA advisory AA25-239A includes a downloadable, machine-readable IOC list in JSON, plus detection and threat-hunting guidance mapped to MITRE ATT&CK. Because indicators change over time, pull the current list directly from CISA and prioritize hunting for the behaviors, such as unexpected router configuration changes and anomalous access to network devices, over static indicators alone.

Stay secure with DeepStrike penetration testing services. Reach out for a quote or customized technical proposal today
Contact Us